Security Wire Weekly:

August, 2008

Aug 28 2008   3:51PM GMT

Rich Mogull on DLP and homeownership



Posted by: SearchSecurity.com Staff
The Nameless Security Podcast

In this episode of the Nameless Security Podcast, Rich Mogull, the founder of Securosis and a former Gartner analyst, discusses the benefits and limitations of DLP products and how life as a disaster medic prepared him for work as a security analyst.

 
icon for podpress  Nameless Security Podcast [20:33m]: Play Now | Play in Popup

Aug 27 2008   5:25PM GMT

SWW: PCI rules halt WEP, push 802.1x



Posted by: SearchSecurity.com Staff
Security Wire Weekly

Bob Russo, general manager of the PCI Security Standards Council explains the changes ahead in version 1.2 of PCI DSS. The use of WEP is being eliminated and antivirus software is required for all operating systems, Russo said.

 
icon for podpress  Security Wire Weekly [16:43m]: Play Now | Play in Popup


Aug 22 2008   10:51AM GMT

Countermeasures against targeted attacks in the enterprise



Posted by: SearchSecurity.com Staff
Threat Monitor

Security organizations often struggle to compensate for unknowing employees who fall victim to social engineering attacks. It’s the unenviable job of information security to prevent that from happening. In this tip, Markus Jakobsson details the ills of social data mining and how technology can help thwart attacks that seek to exploit trusted relationships.

 
icon for podpress  Threat Monitor [7:13m]: Play Now | Play in Popup


Aug 22 2008   8:52AM GMT

Alex Sotirov on Vista memory attacks



Posted by: SearchSecurity.com Staff
The Nameless Security Podcast

Alex Sotirov created quite a stir at Black Hat earlier this month with the paper he and Mark Dowd presented on Vista memory protection attacks. In this episode, he talks about the effect of those attacks, the changing nature of vulnerability research and what lies ahead for application security.

 
icon for podpress  Nameless Security Podcast [13:50m]: Play Now | Play in Popup


Aug 20 2008   3:10PM GMT

SWW: Security Visualization



Posted by: SearchSecurity.com Staff
Security Wire Weekly

Raffael Marty, author of Applied Security Visualization, talks about how security visualization techniques can help improve security decisions. Marty is chief security strategist at log analysis vendor Splunk.

 
icon for podpress  Security Wire Weekly [19:27m]: Play Now | Play in Popup


Aug 18 2008   2:02PM GMT

SWW: Open source Web application firewall



Posted by: SearchSecurity.com Staff
Security Wire Weekly

ModSecurity, the popular open source Web application firewall is getting a new tool that observes and analyzes application traffic and helps establish accepted behavior. In this special edition of Security Wire Weekly, Ivan Ristic, recognized for his work in building the ModSecurity, discusses his new ModProfiler and the challenges of deploying Web application firewalls. Ristic is vice president of security research at Breach Security Inc.

 
icon for podpress  Security Wire Weekly [21:36m]: Play Now | Play in Popup


Aug 13 2008   3:00PM GMT

SWW: Hackers Are People Too



Posted by: SearchSecurity.com Staff
Security Wire Weekly

Ashley Schwartau, director of a new documentary Hackers Are People Too, explains the challenges of making a movie about hackers. The documentary looks at the human side of the hacking community.The film debuted at DEFCON 16.

 
icon for podpress  Security Wire Weekly [14:11m]: Play Now | Play in Popup


Aug 12 2008   2:33PM GMT

The researcher’s-eye view of security



Posted by: SearchSecurity.com Staff
The Nameless Security Podcast

Dino Dai Zovi is the featured guest on the second installment of the Nameless Security Podcast with Dennis Fisher. Dai Zovi is a well-respected researcher whose work on Mac OS X security and virtualization has won him acclaim. He’s also the information security officer at a financial service company, and in this podcast he talks about the ways his dual roles intersect, the real problems with virtualization and the highlights of Black Hat 2008.

 
icon for podpress  Fisher's Nameless Security podcast [17:20m]: Play Now | Play in Popup


Aug 7 2008   11:49AM GMT

SWW: Dan Kaminsky at Black Hat



Posted by: SearchSecurity.com Staff
Security Wire Weekly

Dan Kaminsky gave his Black Hat briefing this week, disclosing full details about the extent of the DNS cache poisoning flaw. Listen to excerpts of his briefing.

 
icon for podpress  Security Wire Weekly [7:46m]: Play Now | Play in Popup


Aug 1 2008   2:51PM GMT

SWW: Wireless Insecurities



Posted by: SearchSecurity.com Staff
Security Wire Weekly

Karsten Nohl, the security researcher who was part of a team that broke the crypto algorithm in the Mifare Classic RFID-based smart card, talks about his upcoming briefing at Black Hat in Las Vegas. Nohl, a University of Virgina graduate student talks about how RFID use could improve security in smart cards.

 
icon for podpress  SWW: Wireless insecurities [21:11m]: Play Now | Play in Popup